QID 982678
QID 982678: Nodejs (npm) Security Update for killing (GHSA-cq77-8jpx-892g)
This affects all versions of package killing up to and including 1.0.6. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cq77-8jpx-892g for updates pertaining to this vulnerability.
Vendor References
- GHSA-cq77-8jpx-892g -
github.com/advisories/GHSA-cq77-8jpx-892g
CVEs related to QID 982678
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cq77-8jpx-892g | killing |
|